
Security Platform Engineer (SIEM)
Sun Life Financial1 hour ago
Tokyo, JapanMid Level / Senior
Responsibilities
- Support and manage the SIEM platform, specifically Splunk Enterprise Security, within the Security Visibility squad.
- Develop security use cases and analyze information systems using cybersecurity techniques.
- Support and maintain security technologies deployed and owned by the Security Visibility function.
- Implement risk-driven security controls and provide subject matter expertise during audits.
- Investigate and respond to security incidents while meeting defined service-level agreements.
- Participate in 24x7 on-call support and major incident management calls.
- Identify business risks and recommend mitigation strategies and security solutions.
- Manage the capacity and resiliency of security systems protecting internal and client data.
- Collaborate with security teams, vendors, and other business teams to improve security posture and practices.
- Plan, research, and develop security policies, standards, procedures, playbooks, and knowledge-base articles.
- Transition and operationalize projects and products, including documentation, RACI development, and team education.
- Use JIRA and Confluence to estimate stories, track assignments, and manage delivery updates.
- Continuously improve security platform and operational processes.
Requirements
- An Information Technology university degree, related college diploma, or equivalent work experience.
- 2–5 years of information security and engineering experience with enterprise-level security technologies.
- Experience with SIEM platforms such as QRadar or Splunk Enterprise Security, IDS/NDR, or threat simulation tools.
- Broad exposure to security disciplines and in-depth experience in incident response or detection engineering.
- Knowledge of security controls, risk management frameworks, NIST, and ISO 2700x standards.
- Experience with endpoint detection and response, intrusion detection, certificate management, email security, and web content filtering technologies.
- Experience developing security policies, standards, and procedures.
- Experience deploying enterprise technology through managed projects.
- Knowledge of networking technologies, firewalls, web application firewalls, intrusion detection and prevention systems, AWS, Microsoft Azure, and disaster recovery.
- Strong troubleshooting, analytical, critical-thinking, communication, leadership, teamwork, investigative, and problem-solving skills.
- Ability to work independently in ambiguous situations, influence stakeholders, and communicate technical security issues to peers and management.
- Ability to complete Reliability Status Clearance and applicable background checks before starting employment and during employment.
Benefits
- Wellness programs supporting mental, physical, and financial health.
- Opportunities to pursue varied career paths and build a professional network.
- Hybrid work arrangement with the choice to work from home or in the office based on business and client needs.
- Reliability Status Clearance is required as a condition of starting employment, including a law enforcement inquiry, credit check, and travel or residence history review.
- The role is posted with a base pay range of 65,000/65 000–105,000/105 000, with eligible employees potentially participating in discretionary incentive plans.